Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
2025-05-01T18:15:57.353
2025-05-27T16:31:11.790
Analyzed
CVSSv3.1: 6.3 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | tenda | w20e_firmware | 15.11.0.6 | Yes |
| Hardware | tenda | w20e | - | No |